Computing.Net > Forums > Security and Virus > AVG Constantly Detecting Virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

AVG Constantly Detecting Virus

Reply to Message Icon

Name: nero_wolfe
Date: July 14, 2007 at 23:43:55 Pacific
OS: XP SVCPK 2
CPU/Ram: 512
Product: Leader Systems
Comment:

My daughter's PC is constantly running slow, despite regular defrags, etc. AVG constantly detecting "repeat" viruses, and IE constantly starting up by itself, and trying to connect to web sites, often multiple instances of IE.

AVG reports Kolweb.G / Downloader.Generic4.ZQI / Collected.11.B / SHeur.ZQ / Downloader.Generic5.QB

This is happening every couple of days.

Any assistance gratefully accepted. If I can't fix this, then I have no option but to rebuild from a clean disk ... :-(

Life Live It!



Sponsored Link
Ads by Google

Response Number 1
Name: MrExacta
Date: July 15, 2007 at 00:22:34 Pacific
Reply:

You've just got a piece of spyware that is loaded on that computer. If you download hijackthis.exe from here:

http://www.merijn.org/files/HiJackT...

boot your computer to safe mode and rename the hijackthis_v2.exe file to something random.exe and run it. You'll probably have a couple winlogon: notify c:\windows\system32\something.dll lines in there.

Write back and let me know what you find.

MrExacta -`


0

Response Number 2
Name: sallyp613
Date: July 18, 2007 at 09:27:07 Pacific
Reply:

I also have a virus / Trojan that AVG detects, deletes, but it returns..

I have a Trojan named> Trojan horse Downloader.Generic4.RGB.. It shows up as being here>

C:\Documents and Settings\Administrator\Application Data\M?crosoft\svchost.exe..

I've tried the Vundofix.exe help program and the VirtuBeGone.exe to no prevail..!! I have Ad-Aware, AVG, WinPatrol, SpyBot S&D.. All find it, but it shows up on my daily AVG scan.. I deleted Internet Explorer, I reinstalled my Java, I only use Firefox to browse.. I'm running Windows 2000... What else do i throw at this nasty..?

sally~


0

Response Number 3
Name: nero_wolfe
Date: July 18, 2007 at 22:13:20 Pacific
Reply:

Thanks MrExacta, here is what I found:

O20 - Winlogon Notify: sstqn - C:\WINDOWS\system32\sstqn.dll
O20 - Winlogon Notify: xxyvvtq - C:\WINDOWS\SYSTEM32\xxyvvtq.dll

Had trouble getting it, as safe mode kept coming up with the Safe Mode option/start message, to run either Safe Mode or System Restore everytime I executed something?


0

Response Number 4
Name: MrExacta
Date: July 19, 2007 at 21:44:26 Pacific
Reply:

yes, that's what is slowing you down. I would download killbox:

http://killbox.net/downloads/KillBo...

When you are in safe mode, you need to run killbox and put the first file name (c:\windows\system32\sstqn.dll) into the location window, choose delete on reboot option, and hit the red/white X button.

Repeat with the other file also. Once completed, run HiJackthis again and see if those items show up with (file missing) after both of them. If so, you should be able to delete them from the list.

Make sure those filenames don't show up anywhere else in the HiJackThis log.

MrExacta -`


0

Response Number 5
Name: nero_wolfe
Date: July 21, 2007 at 20:29:56 Pacific
Reply:

Thanks Mr Exacta, after a few trials and error, I have removed the two dlls and all references to them. Ran a defrag and cleanup and things have improved. No more messages from AVG, or SpyBot about trojans or viruses.

A question though about another dll:

O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\xqtyhcle.dll",realset

I have searched for any information on "xqtyhcle.dll" on Google, Yahoo, etc. and can't find any information on it. Also file itself provides no information, Company, version, etc.

Any thoughts?


0

Related Posts

See More



Response Number 6
Name: MrExacta
Date: July 21, 2007 at 22:54:56 Pacific
Reply:

It looks like a random file name, so it's not a surprise that you can't find any information on it. I would try to delete the entry from HiJackThis, if it won't delete, try the above process through safe-mode.

MrExacta -`


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: AVG Constantly Detecting Virus

Anti virus not auto detect viruses! www.computing.net/answers/security/anti-virus-not-auto-detect-viruses/6514.html

Trojans won't go away! www.computing.net/answers/security/trojans-wont-go-away/21328.html

I have a virus www.computing.net/answers/security/i-have-a-virus/1815.html